Join our Newsletter — 33% off our NHI Course

Credential stuffing and weak passwords: what IAM teams miss

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 21730
Topic starter  

TL;DR: Weak, reused, and already-stolen passwords still let attackers in because many password policies only enforce basic complexity rules, according to Netwrix. Blocking weak credentials at creation time shifts control left, reducing a predictable entry path that reactive tools only see after compromise.

Editorial analysis by NHI Mgmt Group, based on content published by Netwrix: “The left back everyone underestimates”.

Key questions

Q: What should security teams do first when default passwords are still present on privileged accounts and edge devices?

A: Security teams should identify every default credential, especially on internet-facing devices and administrative root accounts, then replace them with unique passwords and enforce banned-password controls.

Q: Why do password reuse and credential stuffing remain so effective?

A: They remain effective because many users still reuse passwords and many environments still accept credentials without enough contextual risk checks.

Q: What are the signs that a password policy is failing in practice?

A: Common warning signs include frequent help desk resets, users making only tiny changes to old passwords, repeated complaints about rejected passwords, and visible workarounds such as password reuse or note-taking.

Practitioner guidance

  • Enforce password screening at creation time Reject weak, reused, leaked, and commonly used passwords before they become valid credentials in the directory or SSO layer.
  • Tune policies beyond complexity rules Replace policy language that only checks length and character variety with controls that block known-bad password patterns and exposed values.
  • Align password controls with credential stuffing risk Review where users authenticate and make sure the same password restrictions apply consistently across remote, hybrid, and cloud-connected entry points.

Bottom line: Weak password policy leaves a predictable account-takeover path open, and credential stuffing succeeds precisely because valid but poor credentials are still accepted.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 4 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21566
 

Weak-password acceptance is a governance failure, not a user-behaviour footnote. Complexity checks alone assume that users will choose unique, non-leaked passwords if rules are sufficiently strict. That assumption fails in practice because attackers target the gap between policy compliance and actual credential quality. The implication is that password governance has to be measured by what it blocks, not by how many rules it publishes.

A question worth separating out:

Q: How should organisations govern password risk across hybrid workforces?

A: Start with the accounts that create the highest exposure, especially third parties and remote personnel, then enforce reuse checks, stronger authentication, and tighter reset controls. Password governance works when it is tied to risk, visibility, and user experience. If teams only publish policy, the weakest users will still work around it.

👉 Read our full editorial: Weak passwords still drive credential stuffing risk across identity


This post was modified 4 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.